aboutcode-org / aboutcode-org/vulnerablecode

Collect commits from dependabot

オープン
#1,130 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
fix-commit
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

We should mine and store the commits made from dependabot in vulnerablecode database.

- Get all the dependabot commits
- Check the package mentioned in that commit is vulnerable or not for example: https://github.com/KoraLinSar/python-socketio/commit/a79f81b8346ab58b012910375569c5d913f0146c this states `Bump sanic from 0.8 to 20.12.6 in /examples/server/sanic` here sanice@0.8 might be vulnerable which can be checked from vulnerablecode https://public.vulnerablecode.io/packages/pkg:pypi/sanic@0.8.0?search=sanic this means this commit is fixing a vulnerable package and the current release of that package can be marked as vulnerable.
- Also check if the commit is merged in main, sometimes dependabot commits might be changing the mock data in test files

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。